Privacy Policy

Your data, our responsibility

We are committed to protecting your personal data and handle it carefully and confidentially — in compliance with the General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (UAVG), and the Medical Treatment Contracts Act (WGBO).

Data Controller

Tandarts Leidseplein is the data controller responsible for processing your personal data as described in this privacy policy. We are registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under number 12345678.

Practice name — Tandarts Leidseplein
Address — Zieseniskade 20 H, 1017 RT Amsterdam, The Netherlands
Telephone — +31 20 62 55 930
Chamber of Commerce no. — 12345678

What personal data do we process?

Depending on the care we provide and the services you use, we process the following categories of personal data. Special category data — such as medical and dental information — is only processed to the extent necessary for your treatment.

Identification data — Full name, address, place of residence, date of birth, and gender.
Contact details — Telephone number and email address for scheduling and confirming appointments.
Citizen Service Number (BSN) — Used solely for submitting claims to your health insurer, as required under the Dutch Health Insurance Act (Zorgverzekeringswet).
Medical and dental record — Medical history, X-rays, treatment notes, medication data, and other clinical information necessary for your treatment.
Insurance details — Name of your health insurer, policy number, and coverage information for billing purposes.
Payment information — Invoice and payment data for the administration of our practice.
Website usage data — Anonymised visitor statistics via analytical cookies (see the Cookies section).

Purposes and legal bases

We only process your personal data for specific, explicitly described, and legitimate purposes. The legal bases are derived from Articles 6 and 9 of the GDPR.

Provision of dental care — Legal basis: performance of a treatment contract (Art. 6(1)(b) GDPR) and medical necessity (Art. 9(2)(h) GDPR). This includes creating and maintaining your dental record.
Legal obligations — Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR). This includes the WGBO retention duty, the Dutch tax retention obligation, and mandatory reports to the Dutch Healthcare Authority (NZa).
Insurance claims and billing — Legal basis: legal obligation (Zorgverzekeringswet) and performance of the treatment contract. Your BSN is used exclusively for this purpose.
Appointment communication — Legal basis: legitimate interest (Art. 6(1)(f) GDPR). We use your contact details to confirm and remind you of appointments.
Newsletter and marketing — Legal basis: your explicit consent (Art. 6(1)(a) GDPR). You may withdraw your consent at any time by emailing [email protected].

Retention periods

We do not retain your personal data longer than necessary for the purposes for which it was collected, unless a legal retention obligation requires a longer period. The main statutory retention periods are:

Medical record (WGBO) — 20 years after the last treatment, or as long as reasonably necessary for good care provision (Art. 7:454(3) Dutch Civil Code). After expiry, data is securely destroyed.
Financial administration — 7 years in accordance with the Dutch tax retention obligation (Art. 52 AWR).
Newsletter and marketing — Until you withdraw your consent. Upon withdrawal, your data will be removed from our marketing lists immediately.
Job applications — 4 weeks after the conclusion of the application process, unless you consent to a longer retention period (maximum 1 year).

Recipients of your data

We only share your personal data with third parties where this is necessary for your treatment, legally required, or where you have given your consent. We have entered into a data processing agreement with all external processors in accordance with Art. 28 GDPR.

Referring specialists — Dentists, oral surgeons, or other healthcare providers to whom we refer you for specialist treatment, only with your knowledge.
Dental laboratory — For the manufacture of prostheses, crowns, bridges, and other dental appliances. Only the data required for the work is shared.
Health insurers — For submitting claims under the Dutch Health Insurance Act. Your BSN is used exclusively for this purpose.
IT service providers — Providers of practice management software, email services, and cloud storage. These parties act solely as processors under instruction from our practice.
Competent authorities — The Dutch Tax Authority (Belastingdienst), the Health and Youth Care Inspectorate (IGJ), or the Dutch Data Protection Authority (AP), where we are legally required to do so.

Your rights as a data subject

Under the GDPR, you have the following rights in relation to your personal data. You may submit your request by emailing [email protected]. We will respond within 4 weeks of receiving your request.

Right of access (Art. 15 GDPR) — You have the right to obtain confirmation of whether your personal data is being processed and to receive a copy of that data.
Right to rectification (Art. 16 GDPR) — You have the right to have inaccurate or incomplete personal data corrected or completed.
Right to erasure (Art. 17 GDPR) — You may request erasure of your data. Please note that this right is limited by the statutory retention obligation for your medical record under the WGBO (20 years).
Right to restriction of processing (Art. 18 GDPR) — You may request that processing of your data be restricted, for example while its accuracy is being verified.
Right to data portability (Art. 20 GDPR) — You have the right to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
Right to object (Art. 21 GDPR) — You may object to the processing of your data on the basis of our legitimate interest, including direct marketing.
Right to withdraw consent — Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out prior to withdrawal.

Security of your data

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or disclosure.

Encryption — All data transmission uses TLS encryption (HTTPS). Data stored on servers is encrypted at rest.
Access control — Only authorised staff have access to your personal data, on a need-to-know basis.
Staff training — All staff are informed of their obligation to treat personal data confidentially and are bound by a duty of confidentiality.
Data breach procedure — In the event of a data breach posing a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority within 72 hours and inform you as soon as possible.

Cookies and website usage

Our website uses cookies — small text files stored by your browser on your device. We use only functional and analytical cookies.

Functional cookies — Necessary for the correct functioning of the website, such as remembering your language preference (NL/EN) and session data. No consent is required for these cookies.
Analytical cookies — We use anonymised statistics to understand and improve the use of our website. These cookies do not trace your visit back to a specific person.
No tracking or marketing cookies — We do not place cookies for advertising purposes or for tracking your online behaviour outside our website, unless you have given your explicit consent.
Disabling cookies — You can disable cookies via your browser settings. Please note that this may limit certain website functionality.

Complaints and supervision

We make every effort to process your data carefully. If you have a complaint about how we handle your personal data, we ask you to contact us first so we can resolve your complaint as quickly as possible.

Contact us — Send an email to [email protected] or call +31 20 62 55 930. We aim to respond within 5 working days.
Dutch Data Protection Authority — If you are not satisfied with our response, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (AP) at autoriteitpersoonsgegevens.nl. The AP is the independent supervisory authority for data protection in the Netherlands.
Data protection contact — For questions about the processing of your personal data, you may contact our practice manager at the email address above.

Changes to this privacy policy

We reserve the right to amend this privacy policy. Changes will be published on this page with the date of the latest update. For significant changes, we will notify you by email or via a prominent notice on our website. The most current version is always available at https://tandartsleidseplein.nl/en/privacy-policy.

Last updated — 25 May 2026.
Applicable law — This privacy policy has been drawn up in accordance with the General Data Protection Regulation (GDPR / EU 2016/679), the Dutch GDPR Implementation Act (UAVG), the Medical Treatment Contracts Act (WGBO), and other applicable Dutch legislation.